Division of Engineering and Computer Science, Cybersecurity, Oklahoma Christian University.
* Corresponding Author
International Journal of Science and Research Archive, 2026, 21(02), 176–180
Article DOI: 10.30574/ijsra.2026.21.1.1852
Received on 29 August 2026; revised on 04 October 2026; accepted on 06 October 2026
Connected medical devices, including infusion pumps, patient monitors, implantable devices, and remote monitoring platforms, have expanded the attack surface of modern healthcare delivery beyond what traditional IT security practices were designed to address. This paper's objective is to examine threat modeling as a structured, lifecycle-based discipline for identifying and mitigating cybersecurity risks specific to medical Internet of Things (IoMT) devices, and to argue that patient-safety impact must be integrated explicitly into existing threat-modeling methodologies rather than treated as a secondary concern. The methodology consisted of a targeted literature and documentation review covering regulatory guidance, peer-reviewed security research, and documented device vulnerability cases, combined with an applied walkthrough of established threat-modeling methodologies (STRIDE, DREAD, PASTA, and attack-tree analysis) against a representative device scenario. Results show that generic IT threat-modeling approaches underweight safety-critical consequences and do not account for the extended regulatory lifecycles, legacy protocols, and patch constraints characteristic of medical devices, and that documented real-world cases, including confirmed vulnerabilities in implantable cardiac devices, demonstrate that these risks are not theoretical. The paper concludes that threat modeling delivers the most value when applied continuously across a device's full lifecycle, from procurement through post-deployment monitoring, and when existing scoring methodologies are explicitly adapted to weight patient-safety severity. Future work should focus on standardized, patient-safety-weighted scoring extensions and empirical evaluation of threat-modeling programs in real hospital deployments.
Medical Iot Security; Threat Modeling; STRIDE; Patient Safety; Medical Device Cybersecurity
Preview Article PDF
Adewumi Busayo Adelemi. MEDICAL IOT THREAT MODELING: A LIFECYCLE-BASED FRAMEWORK FOR INTEGRATING CYBERSECURITY RISK AND PATIENT SAFETY. International Journal of Science and Research Archive, 2026, 21(02), 176–180. Article DOI: https://doi.org/10.30574/ijsra.2026.21.1.1852.






